CVE-2026-2694 | Events Calendar Plugin up to 6.15.16 on WordPress can_edit/can_delete improper authorization
A vulnerability described as critical has been identified in Events Calendar Plugin up to 6.15.16 on WordPress. This issue affects the function can_edit/can_delete. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-2694. The attack may be performed from remote. There is no available exploit.